NARA CUI Registry codifies PRVCY marking for federal PII
The General Privacy category splits into basic and specified authority markings, but contractors inheriting agency PII should first check their agency's implementing policies, not just the registry.
TL;DR
NARA's [CUI Registry](https://www.deepfathom.ai/glossary#cui-registry) lists the General Privacy category (PRVCY) with its associated safeguarding authorities and banner markings under the CUI program established by Executive Order 13556 and 32 CFR Part 2002. The category covers personal information as defined in OMB M-17-12 and "means of identification" under 18 USC 1028(d)(7). The registry distinguishes between basic authorities (which use CUI or the alternative banner CUI//PRVCY) and OMB M-17-12 as the listed specified authority, which carries CUI//SP-PRVCY. Agency personnel and contractors should consult their agency's CUI implementing policies for guidance; the registry is the Government-wide baseline, not a substitute for agency-level direction.
NARA's [CUI Registry](https://www.deepfathom.ai/glossary#cui-registry) entry for the General Privacy category documents the authorized markings for unclassified information that requires safeguarding because it contains personal information. The category description pulls from OMB M-17-12's definition of personally identifiable information and 18 USC 1028(d)(7)'s definition of "means of identification."
The registry table distinguishes two tiers. Most of the listed safeguarding authorities (from the Privacy Act at 5 USC 552a(b) through OMB Circular A-130) are designated as basic, meaning the information carries CUI as its banner marking. The alternative banner marking for these basic authorities is CUI//PRVCY. One authority, OMB M-17-12, is listed as specified, carrying the banner CUI//SP-PRVCY.
What the registry is and isn't
The CUI Registry is the Government-wide online repository for Federal-level guidance on CUI policy and practice, managed by NARA's Information Security Oversight Office as the CUI Executive Agent. But it isn't an operational playbook. The registry itself notes that agency personnel and contractors "should first consult their agency's CUI implementing policies and program management for guidance." Each agency's implementation may impose additional handling requirements beyond the registry baseline.
The practical consequence for contractors: when you receive CUI marked with a PRVCY banner from a federal agency, the marking tells you what category of safeguarding obligation applies. But the specifics of how that agency expects you to handle, store, and disseminate that information live in agency-level policy, not the registry page.
Legacy markings haven't disappeared
GSA's CUI Program Guide, updated January 2024, addresses what happens when CUI arrives with legacy markings like SBU, FOUO, or OUO: apply "necessary protections and policies to safeguard according to the law, regulation, or government-wide policy that covers that as protected information." The registry provides the standardized marking scheme going forward, but agencies have migrated at different speeds, and contractors will continue to encounter pre-CUI markings on older holdings for some time.
Published ·Deep Fathom